A proof without a venue is a demonstration. The previous article in this series showed that zero knowledge proofs, hardware attestation, and committed configuration can bind an AI output to a model fingerprint and a policy. But if those artifacts live in a database the operator controls, the audit gap from the first article survives intact: the system that would need to record tampering is the operator's own system. What turns cryptographic material into evidence is where it is published. The requirements for that place are precise, and they are worth spelling out.
What a Substrate Must Guarantee
Five properties define an attestation substrate fit for audit. It must be append-only, so records can be added but never edited or deleted. Its timestamps must come from a source independent of the operator, set by a network rather than a server clock anyone can adjust. It must be publicly verifiable, meaning any party holding the record and access to the chain can confirm it without permission from the operator. It must carry small payloads, hashes rather than raw data, so commitments establish integrity without exposing confidential inputs, outputs, or model weights. And it must bind signatures to identity, so every record has a legal entity standing behind it rather than an anonymous hash nobody owns.
Conventional infrastructure fails these tests not because engineers are careless but because editability is a feature everywhere else. A substrate designed for attestation inverts the default: the write is permanent, and that permanence is the product.
The Record Itself
The unit of the substrate is a small structured record. A practical shape combines the elements from Part 2: the model fingerprint, a hash of the weights; the configuration hash, covering tokenizer and preprocessing; the policy hash, covering the system prompt, guardrails, and sampling parameters; the input hash and the output hash; optionally a reference to a zk proof or a hardware attestation quote; a timestamp; and the signer's identity. Each element is a hash, so the whole record is a few hundred bytes regardless of how large the model is or how long the conversation ran.
Volume is handled the same way blockchains handle volume. High-stakes decisions, payment authorizations, regulated determinations, contract executions, can anchor one record per decision. High-volume flows can aggregate per-decision records into a Merkle tree and anchor only the root, with the tree available on request. Sampling strategies from Part 2 compose cleanly: every decision gets a committed record, a subset gets proofs, and the substrate holds the lot.
Why Anchor to Bitcoin
The integrity of a commitment inherits from whatever anchors it. Bitcoin has produced a block roughly every ten minutes since January 2009. That schedule has never stopped, and no party has rewritten the chain's history. A commitment included in that history is a commitment an auditor can check against infrastructure nobody in the dispute controls, which is the property that matters when the parties auditing each other include regulators and counterparties.
Mintlayer extends that anchor with settlement mechanics designed for records and assets. The chain is secured by Bitcoin's proof of work rather than a new token's validator set. The UTXO ownership model keeps supply and record ownership auditable transaction by transaction. Smart contract logic is deliberately non-Turing-complete, which narrows the attack surface for the settlement layer that has to keep functioning when it is adversarial. Assets move through native atomic swaps rather than wrapped intermediaries. On this base, an attestation record is a UTXO commitment: owned, timestamped, and as permanent as the chain itself, with Mintlayer Web Services handling the issuance and settlement plumbing so organizations do not operate raw chain infrastructure to keep an audit trail.
From Proof to Product
This is not a hypothetical stack. Mintlayer's IP Notary commits fingerprints of digital artifacts, model weights, datasets, evaluation suites, to the chain, connecting directly to the provenance series published here in July: the same hash-and-anchor machinery that timestamps a design file timestamps a model fingerprint. Compliance Sentinel builds regulatory audit trails from the same records, which is the machinery an AI accountability layer needs underneath it. And the agent payments infrastructure connects to the agentic commerce question examined in earlier research: an autonomous payment whose authorization and settlement both reference attestation records is an agent payment a counterparty can audit after the fact.
For enterprises, the practical uses arrive before the mandates do. Procurement teams can ask a vendor to demonstrate which model answered a customer, and receive a record rather than a reassurance. Dispute resolution gets an evidence object with an independent timestamp instead of a screenshot and an affidavit. Insurers underwriting AI liability can price against records rather than questionnaires. The record exists or it does not, and the difference is checkable by anyone.
The Regulatory Timeline
The EU AI Act's schedule gives the substrate a date. Article 50 transparency duties for chatbots and generative systems have applied since 2 August 2026. The Digital Omnibus moved the high-risk obligations, provider record-keeping under Article 12 and deployer duties under Article 26 including log retention, to 2 December 2027, with high-risk systems embedded in regulated products generally arriving in August 2028. Penalty ceilings stand at EUR 15 million or 3 percent of worldwide annual turnover for most violations, and EUR 35 million or 7 percent for prohibited practices. An organization that starts anchoring attestations now has records covering the period regulators will eventually ask about, rather than a plan to start when asked.
What This Does Not Solve
The honest boundaries are the ones from Part 2, restated at the system level. Anchoring proves that a record existed at a time and has not changed; it does not prove the model's output was true, wise, or lawful, and it does not prove the deployer configured the system honestly. Signatures bind records to keys, and process, contracts, and law bind keys to entities. The substrate's job is narrow and essential: it makes the record's existence, integrity, and time checkable by anyone, which is precisely what the operator-controlled alternatives cannot offer. Proofs establish what computation happened, commitments establish what was claimed, and a Bitcoin-anchored record establishes when, and that nobody has changed the story since.
This article is for informational purposes only and does not constitute investment advice.
Mintlayer Web Services provides Bitcoin-native infrastructure for anchoring the attestations your audits, counterparties, and regulators will ask to see. Learn more →